Exploitation Summary
EIP tracks 1 public exploit for EIP-2026-106308. PoCs published by Besim.
AI-analyzed exploit summary This exploit demonstrates an arbitrary file deletion vulnerability in CuteNews 2.1.2. The vulnerability is triggered via a POST request to the Media Manager, allowing low-privileged users to delete arbitrary files due to insecure use of the unlink() function.
Description
CuteNews 2.1.2 - Arbitrary File Deletion
Exploits (1)
exploitdb
WORKING POC
by Besim · textwebappsphp
https://www.exploit-db.com/exploits/48447
This exploit demonstrates an arbitrary file deletion vulnerability in CuteNews 2.1.2. The vulnerability is triggered via a POST request to the Media Manager, allowing low-privileged users to delete arbitrary files due to insecure use of the unlink() function.
Classification
Working Poc 90%
Attack Type
Other
Complexity
Trivial
Reliability
Reliable
Target:
CuteNews 2.1.2
Auth required
Prerequisites:
Valid session cookie (CUTENEWS_SESSION) · Access to the Media Manager functionality
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026
Full analysis →
Details
Status
pre_cve
Tracked Since
Feb 18, 2026